ATT&CKReferencesCyber Forensicator Silence Jan 2019

Cyber Forensicator Silence Jan 2019

Skulkin, O.. (2019, January 20). Silence: Dissecting Malicious CHM Files and Performing Forensic Analysis. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupSilence

Silence has used environment variable string substitution for obfuscation.

T1053.005
Scheduled Task
GroupSilence

Silence has used scheduled tasks to stage its operation.

T1059.001
PowerShell
GroupSilence

Silence has used PowerShell to download and execute payloads.

T1059.003
Windows Command Shell
GroupSilence

Silence has used Windows command-line to run commands.

T1059.005
Visual Basic
GroupSilence

Silence has used VBS scripts.

T1059.007
JavaScript
GroupSilence

Silence has used JS scripts.

T1070.004
File Deletion
GroupSilence

Silence has deleted artifacts, including scheduled tasks, communicates files from the C2 and other logs.

T1204.002
Malicious File
GroupSilence

Silence attempts to get users to launch malicious attachments delivered via spearphishing emails.

T1218.001
Compiled HTML File
GroupSilence

Silence has weaponized CHM files in their phishing campaigns.

T1566.001
Spearphishing Attachment
GroupSilence

Silence has sent emails with malicious DOCX, CHM, LNK and ZIP attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.